RHEL 2.1 : nfs-utils (RHSA-2003:207)

critical Nessus Plugin ID 12405

Synopsis

The remote Red Hat host is missing a security update.

Description

Updated nfs-utils packages are available that fix a remotely exploitable Denial of Service vulnerability.

The nfs-utils package provides a daemon for the kernel NFS server and related tools.

Janusz Niewiadomski found a buffer overflow bug in nfs-utils version 1.0.3 and earlier. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). It is not believed that this bug could lead to remote arbitrary code execution.

Users are advised to update to these erratum packages, which contain a backported security patch supplied by the nfs-utils maintainers and are not vulnerable to this issue.

Solution

Update the affected nfs-utils package.

See Also

https://access.redhat.com/security/cve/cve-2003-0252

http://www.nessus.org/u?63679533

https://access.redhat.com/errata/RHSA-2003:207

Plugin Details

Severity: Critical

ID: 12405

File Name: redhat-RHSA-2003-207.nasl

Version: 1.27

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:nfs-utils, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 7/14/2003

Vulnerability Publication Date: 8/18/2003

Reference Information

CVE: CVE-2003-0252

RHSA: 2003:207